WP Social Follower Security & Risk Analysis

wordpress.org/plugins/wp-social-followers-count

A widget plugin to add links of social networking sites.

0 active installs v1.0.0 PHP + WP 2.8+ Updated Jun 23, 2017
social-iconssocial-linkssocial-mediasocial-networkwp-social-widget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Social Follower Safe to Use in 2026?

Generally Safe

Score 85/100

WP Social Follower has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The wp-social-followers-count plugin v1.0.0 exhibits a seemingly strong security posture on the surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero-entry point attack surface. Furthermore, the absence of critical, high, or medium severity vulnerabilities in its history, along with no recorded critical or high taint flows and the use of prepared statements for all SQL queries, are positive indicators. However, the static analysis reveals significant concerns regarding output escaping, with only 40% of outputs being properly escaped. This leaves a substantial portion of the plugin's output vulnerable to cross-site scripting (XSS) attacks if user-supplied data is not handled meticulously. The lack of any capability checks or nonce checks on entry points, while technically there are no entry points, suggests a potential for future vulnerabilities if new features are added without proper security considerations. The plugin also makes several external HTTP requests, which could be a vector for other types of attacks if not validated properly. While the vulnerability history is clean, the lack of robust output escaping and authorization checks presents a real risk.

Key Concerns

  • Significant unescaped output (60% of outputs)
  • No capability checks on entry points
  • No nonce checks on entry points
Vulnerabilities
None known

WP Social Follower Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP Social Follower Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
91
61 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
5
Bundled Libraries
0

Output Escaping

40% escaped152 total outputs
Attack Surface

WP Social Follower Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionwp_enqueue_scriptswp-social-follower.php:16
filterhttps_ssl_verifywp-social-follower.php:437
filterhttps_ssl_verifywp-social-follower.php:458
actionwidgets_initwp-social-follower.php:555
Maintenance & Trust

WP Social Follower Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedJun 23, 2017
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

WP Social Follower Developer Profile

Mahfuzur Rahman

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Social Follower

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-social-followers-count/style.css/wp-content/plugins/wp-social-followers-count/font-awesome.min.css

HTML / DOM Fingerprints

CSS Classes
wp-social-followers-count
Data Attributes
id="wp_social_authors"
FAQ

Frequently Asked Questions about WP Social Follower